Analyzing Network Flow Data With Netflow

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and applies statistical analysis to identify flows with abnormal byte counts, connection durations, and periodic timing patterns.

agentflocks 3a1ca03 5 files · 23.9 KB Updated

File contents

agentflocks/flocks/tree/main/.flocks/flockshub/plugins/skills/Anthropic-Cybersecurity-Skills/analyzing-network-flow-data-with-netflow commit 3a1ca033b0

Frequently asked questions

npx skillmds@latest add agentflocks/analyzing-network-flow-data-with-netflow